setup_ipv6.go 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106
  1. package bridge
  2. import (
  3. "fmt"
  4. "io/ioutil"
  5. "net"
  6. "github.com/Sirupsen/logrus"
  7. "github.com/vishvananda/netlink"
  8. )
  9. var bridgeIPv6 *net.IPNet
  10. const (
  11. bridgeIPv6Str = "fe80::1/64"
  12. ipv6ForwardConfPerm = 0644
  13. ipv6ForwardConfDefault = "/proc/sys/net/ipv6/conf/default/forwarding"
  14. ipv6ForwardConfAll = "/proc/sys/net/ipv6/conf/all/forwarding"
  15. )
  16. func init() {
  17. // We allow ourselves to panic in this special case because we indicate a
  18. // failure to parse a compile-time define constant.
  19. if ip, netw, err := net.ParseCIDR(bridgeIPv6Str); err == nil {
  20. bridgeIPv6 = &net.IPNet{IP: ip, Mask: netw.Mask}
  21. } else {
  22. panic(fmt.Sprintf("Cannot parse default bridge IPv6 address %q: %v", bridgeIPv6Str, err))
  23. }
  24. }
  25. func setupBridgeIPv6(config *networkConfiguration, i *bridgeInterface) error {
  26. procFile := "/proc/sys/net/ipv6/conf/" + config.BridgeName + "/disable_ipv6"
  27. ipv6BridgeData, err := ioutil.ReadFile(procFile)
  28. if err != nil {
  29. return fmt.Errorf("Cannot read IPv6 setup for bridge %v: %v", config.BridgeName, err)
  30. }
  31. // Enable IPv6 on the bridge only if it isn't already enabled
  32. if ipv6BridgeData[0] != '0' {
  33. if err := ioutil.WriteFile(procFile, []byte{'0', '\n'}, ipv6ForwardConfPerm); err != nil {
  34. return fmt.Errorf("Unable to enable IPv6 addresses on bridge: %v", err)
  35. }
  36. }
  37. _, addrsv6, err := i.addresses()
  38. if err != nil {
  39. return err
  40. }
  41. // Add the default link local ipv6 address if it doesn't exist
  42. if !findIPv6Address(netlink.Addr{IPNet: bridgeIPv6}, addrsv6) {
  43. if err := netlink.AddrAdd(i.Link, &netlink.Addr{IPNet: bridgeIPv6}); err != nil {
  44. return &IPv6AddrAddError{IP: bridgeIPv6, Err: err}
  45. }
  46. }
  47. // Store bridge network and default gateway
  48. i.bridgeIPv6 = bridgeIPv6
  49. i.gatewayIPv6 = i.bridgeIPv6.IP
  50. return nil
  51. }
  52. func setupGatewayIPv6(config *networkConfiguration, i *bridgeInterface) error {
  53. if config.FixedCIDRv6 == nil {
  54. return &ErrInvalidContainerSubnet{}
  55. }
  56. if !config.FixedCIDRv6.Contains(config.DefaultGatewayIPv6) {
  57. return &ErrInvalidGateway{}
  58. }
  59. if _, err := ipAllocator.RequestIP(config.FixedCIDRv6, config.DefaultGatewayIPv6); err != nil {
  60. return err
  61. }
  62. // Store requested default gateway
  63. i.gatewayIPv6 = config.DefaultGatewayIPv6
  64. return nil
  65. }
  66. func setupIPv6Forwarding(config *networkConfiguration, i *bridgeInterface) error {
  67. // Get current IPv6 default forwarding setup
  68. ipv6ForwardDataDefault, err := ioutil.ReadFile(ipv6ForwardConfDefault)
  69. if err != nil {
  70. return fmt.Errorf("Cannot read IPv6 default forwarding setup: %v", err)
  71. }
  72. // Enable IPv6 default forwarding only if it is not already enabled
  73. if ipv6ForwardDataDefault[0] != '1' {
  74. if err := ioutil.WriteFile(ipv6ForwardConfDefault, []byte{'1', '\n'}, ipv6ForwardConfPerm); err != nil {
  75. logrus.Warnf("Unable to enable IPv6 default forwarding: %v", err)
  76. }
  77. }
  78. // Get current IPv6 all forwarding setup
  79. ipv6ForwardDataAll, err := ioutil.ReadFile(ipv6ForwardConfAll)
  80. if err != nil {
  81. return fmt.Errorf("Cannot read IPv6 all forwarding setup: %v", err)
  82. }
  83. // Enable IPv6 all forwarding only if it is not already enabled
  84. if ipv6ForwardDataAll[0] != '1' {
  85. if err := ioutil.WriteFile(ipv6ForwardConfAll, []byte{'1', '\n'}, ipv6ForwardConfPerm); err != nil {
  86. logrus.Warnf("Unable to enable IPv6 all forwarding: %v", err)
  87. }
  88. }
  89. return nil
  90. }